logo

Database

Improper resource allocation In org.apache.commons:commons-compress

Description

Uncontrolled Resource Consumption in Apache Commons Compress Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress before 1.4.1 allows remote attackers to cause a denial of service (CPU consumption) via a file with many repeating inputs.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

References

1. https://github.com/apache/commons-compress/commit/020c03d8ef579e80511023fb46ece30e9c3dd27d2. https://github.com/apache/commons-compress/commit/0600296ab8f8a0bbdfedd483f51b38005eb8e34e3. https://github.com/apache/commons-compress/commit/1ce57d976c4f25fe99edcadf079840c278f3cb844. https://github.com/apache/commons-compress/commit/2ab2fcb356753927afaa731b9d2dcc47d30834085. https://github.com/apache/commons-compress/commit/654222e628097763ee6ca561ae77be5c066661736. https://github.com/apache/commons-compress/commit/6ced422bf5eca3aac05396367bafb33ec21bf74e7. https://github.com/apache/commons-compress/commit/6e95697e783767f3549f00d7d2e1b002eac4a3d48. https://github.com/apache/commons-compress/commit/8f702469cbf4c451b6dea349290bc4af0f6f76c79. https://github.com/apache/commons-compress/commit/b06f7b41c936ef1a79589d16ea5c1d8b93f71f6610. https://github.com/apache/commons-compress/commit/cca0e6e5341aacddefd4c4d36cef7cbdbc2a877711. https://github.com/apache/commons-compress/commit/ea31005111f0abede7e43e4ba0012e62e0808b2212. https://github.com/apache/commons-compress/commit/fdd7459bc5470e90024dbe762249166481cce76913. https://web.archive.org/web/20200517014414/http://www.securitytracker.com/id?102709614. https://www.oracle.com/security-alerts/cpujan2021.html15. https://web.archive.org/web/20130525085523/http://www.securityfocus.com/bid/5367616. https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@<solr-user.lucene.apache.org>17. https://exchange.xforce.ibmcloud.com/vulnerabilities/7585718. http://ant.apache.org/security.html19. http://archives.neohapsis.com/archives/bugtraq/2012-05/0130.html20. http://commons.apache.org/compress/security.html21. http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081697.html22. http://lists.fedoraproject.org/pipermail/package-announce/2012-June/081746.html23. http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105049.html24. http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105060.html25. http://packetstormsecurity.org/files/113014/Apache-Commons-Compress-Apache-Ant-Denial-Of-Service.html26. http://www-01.ibm.com/support/docview.wss?uid=swg2164404727. http://www.openwall.com/lists/oss-security/2023/09/13/3
FLAT-VJIAB – Vulnerability | Fluid Attacks Database